<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Legacy DHCP Relay services vs R80.x - gw not configured as relay in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-DHCP-Relay-services-vs-R80-x-gw-not-configured-as-relay/m-p/100903#M7871</link>
    <description>&lt;P&gt;Thank you PhoneBoy&lt;/P&gt;&lt;P&gt;It is a step forward to know that.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Nov 2020 14:10:22 GMT</pubDate>
    <dc:creator>Firewallteam_DE</dc:creator>
    <dc:date>2020-11-02T14:10:22Z</dc:date>
    <item>
      <title>Legacy DHCP Relay services vs R80.x - gw not configured as relay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-DHCP-Relay-services-vs-R80-x-gw-not-configured-as-relay/m-p/100658#M7841</link>
      <description>&lt;P&gt;Hello Mates&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;We are preparing Migration of MDS to R80 and following is the example pre-check warning:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Two possible options to solve the problem: 1). Remove legacy DHCP Relay services and add new DHCP Relay services. See sk104114 for instructions. This is the recommended action if managing only R77.20 gateways and above. 2). Keep legacy DHCP Relay services and make changes to the Gateways and the Security Management Servers. See sk98839 for instructions. Do this if managing any gateways which are older than R77.20. Legacy DHCP Relay service(s): bootp, dhcp-relay, dhcp-rep-localmodule, dhcp-req-localmodule&amp;nbsp;&amp;nbsp; Some of the legacy DHCP Relay service(s) are members of the following rulebase(s): Policy skibidabdab_Prod, rules: XY. For more information, see sk104114 or sk98839.&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;We have plenty of gateways managed by CMAs which policies have Legacy DHCP relay services objects in its rules. Current GW batch has all R70.20 and above.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The article mentions that in case the gateways are not configured as DHCP agents &lt;/STRONG&gt;&lt;STRONG&gt;(none are, as I checked on GWs: RTGRTG0019&amp;nbsp; BOOTP: Feature is not enabled )&lt;/STRONG&gt;&lt;STRONG&gt;,&lt;/STRONG&gt; &lt;STRONG&gt;then we should follow all sections except &lt;/STRONG&gt;&lt;STRONG&gt;&lt;I&gt;"DHCP Relay Configuration":&lt;/I&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;I&gt;“If Gaia OS will not be configured as a DHCP Relay Agent and will only be used to secure DHCP relay traffic between a separate DHCP Relay Agent and a DHCP Server, follow all instructions except for the "DHCP Relay Configuration" section, and modify the security policy with the correct IPs for the DHCP Relay and DHCP server.”&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;According to initial error we should only change the Services in policies to newer ones (those in right replace with those in left - attached):&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;BUT SK article discusses all other configurations in its sections (excluding &lt;/STRONG&gt;&lt;STRONG&gt;&lt;I&gt;DHCP Relay Configuration&lt;/I&gt;&lt;/STRONG&gt;&lt;STRONG&gt; part) like Hotfix, &lt;/STRONG&gt;&lt;I&gt;fwx_dhcp_relay_nat&lt;/I&gt;&lt;STRONG&gt; parameter, &lt;/STRONG&gt;&lt;I&gt;dhcp_objects create,&lt;/I&gt;&lt;STRONG&gt; table.def modifications, global properties and various precautions in rules related to DHCP traffic handling…. Many times referring to gateway as relay agent which is not our case.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How should we interpret that information?&lt;/STRONG&gt;&lt;STRONG&gt; Is it enough to just replace the objects in the policies or do we have to go through all other mentioned configurations? &lt;/STRONG&gt;&lt;STRONG&gt;Gateways are only securing the DHCP traffic, they are not acting as relays&lt;/STRONG&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I searched forum for posts related to this and although there are plenty, following one seems as relevant to the case:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://community.checkpoint.com/t5/Policy-Management/Need-to-change-bootp-config-to-dhcp-request-when-upgradig/m-p/53664" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Policy-Management/Need-to-change-bootp-config-to-dhcp-request-when-upgradig/m-p/53664&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Can somebody confirm this is safe to assume?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 13:17:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-DHCP-Relay-services-vs-R80-x-gw-not-configured-as-relay/m-p/100658#M7841</guid>
      <dc:creator>Firewallteam_DE</dc:creator>
      <dc:date>2020-10-30T13:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy DHCP Relay services vs R80.x - gw not configured as relay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-DHCP-Relay-services-vs-R80-x-gw-not-configured-as-relay/m-p/100762#M7858</link>
      <description>&lt;P&gt;&lt;STRONG&gt;e&lt;/STRONG&gt;It should be enough to replace the relevant objects in the policy.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2020 06:41:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-DHCP-Relay-services-vs-R80-x-gw-not-configured-as-relay/m-p/100762#M7858</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-01T06:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy DHCP Relay services vs R80.x - gw not configured as relay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-DHCP-Relay-services-vs-R80-x-gw-not-configured-as-relay/m-p/100903#M7871</link>
      <description>&lt;P&gt;Thank you PhoneBoy&lt;/P&gt;&lt;P&gt;It is a step forward to know that.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 14:10:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-DHCP-Relay-services-vs-R80-x-gw-not-configured-as-relay/m-p/100903#M7871</guid>
      <dc:creator>Firewallteam_DE</dc:creator>
      <dc:date>2020-11-02T14:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy DHCP Relay services vs R80.x - gw not configured as relay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-DHCP-Relay-services-vs-R80-x-gw-not-configured-as-relay/m-p/100905#M7872</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;Hello, I can see you replied quite confidently on following thread -&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Policy-Management/Need-to-change-bootp-config-to-dhcp-request-when-upgradig/m-p/53664" target="_blank"&gt;https://community.checkpoint.com/t5/Policy-Management/Need-to-change-bootp-config-to-dhcp-request-when-upgradig/m-p/53664&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;using the new DHCP services is not mandatory.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Using the bootp like you does, there is&amp;nbsp; no need to change to the new dhcp services.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104114" target="_blank" rel="noopener noopener noreferrer"&gt;Configuration of IPv4 BOOTP/DHCP Relay using new services&lt;/A&gt;&amp;nbsp;describes really good the new DHCp services and there need or not.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;For youre use case, snip from the document:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"For backwards compatibility, the legacy DHCP (BOOTP/DHCP) services can still be used with newer Security Gateways and Security Management Servers."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The new DHCP services allows an improved configuration of the rules for DHCP relay.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Wolfgang&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Do you know anyone who can confirm this? There are many policies with Legacy DHCP in our environment and would be easier to not replace them if only some improved handling is benefit currently.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 14:19:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-DHCP-Relay-services-vs-R80-x-gw-not-configured-as-relay/m-p/100905#M7872</guid>
      <dc:creator>Firewallteam_DE</dc:creator>
      <dc:date>2020-11-02T14:19:53Z</dc:date>
    </item>
  </channel>
</rss>

